Home > Data Management All-in-One Guides > Corporate compliance tutorial > HIPAA / Healthcare compliance > Dealing with HIPAA > HIPAA security rules broken down
All-in-One Guides: Corporate compliance tutorial:
EMAIL THIS
 START   COMPLIANCE IN THE ENTERPRISE   SARBANES-OXLEY COMPLIANCE   HIPAA / HEALTHCARE COMPLIANCE   COMPLIANCE AND AUDITING   
HIPAA / Healthcare compliance


Dealing with HIPAA
<< PREVIOUS | NEXT >>: Reading between the HIPAA guidelines

HIPAA security rules broken down

By Bill Brenner, News Writer
15 Mar 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

HIPAA's security requirements affect companies that store and transmit protected health information electronically. This includes healthcare providers, insurers and clearinghouses.

Enterprises that serve clients in the healthcare industry -- laboratories, collection agencies and lawyers, for example -- must also implement protections to secure

There's no cookie-cutter approach for everyone. The standards don't specify any particular technology to adopt. They outline what must be done, not how to do it.


There's no cookie-cutter approach for everyone. The standards don't specify any particular technology to adopt. They outline what must be done, not how to do it.

Organizations trying to figure out how to apply the standards must take into account their size, complexity, capabilities, compliance costs and the potential risks to their electronically protected health information.

Generally speaking, HIPAA security requires that:

  • Administrative safeguards be in place to manage the selection and execution of security measures.
  • Physical safeguards be in place to protect electronic systems and related buildings and equipment from environmental hazards and unauthorized intrusion.
  • Technical safeguards be in place, including an automated processes to protect data and control access to it.
  • Risk assessments are conducted and that security policies and procedures are documented.
  • Organizations have a device to screen traffic from the Internet such as a firewall.

Tthe HIPAA security rules are outlined by the Department of Health and Human Services. ,
Related stories from the series
HIPAA rules force health insurers to secure sensitive data: IT security and compliance professionals said the massive patient privacy law is a bitter pill for some to swallow and the best prescription for others to follow.

Got a health plan? Then your company's covered under HIPAA. The HIPAA data security rules must be observed by any enterprise that offers its employees a healthcare plan.

Covered entities with the exception of small health plans must comply with the security requirements by April 21. Small health plans -- those with fewer than 50 employees -- must comply by April 21, 2006.

Learn about HIPAA privacy and security by reading our series.

Note: This information was culled from various sources, including the Department of Health and Human Services, ArticSoft, HIPAAacademy.net and the Centers for Medicare & Medicaid Services (CMS).

Tags: Dealing with HIPAAHealthcare data managementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Reading between the HIPAA guidelines
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Dealing with HIPAA
Healthcare users struggle with HIPAA
Reading between the HIPAA guidelines

Healthcare data management
Data governance software has unexpected benefits for LTC Partners
Business intelligence in healthcare: Special report
What industries are using enterprise information management (EIM)?
Top 13 master data management (MDM) buzzwords and definitions
New data analysis apps part of IBM's industry-specific BI vision
Data destruction requires more than just encryption
Customer data integration and data warehouses for the healthcare sector
Business intelligence in healthcare demands a balance between privacy and insight
Data mining in the healthcare industry
Spotlight on regulatory compliance

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
HIPAA  (SearchDataManagement.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Data Management: Business Intelligence, Data Integration, Data Compliance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts